CVE-2025-47708: Enterprise MFA - TFA for Drupal - Critical - Cross Site Request Forgery - SA-CONTRIB-2025-054
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Cross Site Request Forgery.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47708?
CVE-2025-47708 is classified as a cross-site request forgery (CSRF) vulnerability affecting certain versions of Drupal Enterprise MFA - TFA.
How do I fix CVE-2025-47708?
To remediate CVE-2025-47708, update Drupal Enterprise MFA - TFA for Drupal to version 4.7.0 or greater, or 5.2.0 or greater.
Which versions of Drupal are affected by CVE-2025-47708?
CVE-2025-47708 affects Drupal Enterprise MFA - TFA for Drupal versions before 4.7.0 and from 5.0.0 before 5.2.0.
Is CVE-2025-47708 a critical vulnerability?
CVE-2025-47708 is considered a serious vulnerability due to its potential to allow unauthorized actions on behalf of the user.
What type of attacks can CVE-2025-47708 facilitate?
CVE-2025-47708 can facilitate cross-site request forgery (CSRF) attacks, allowing attackers to perform actions without user consent.